VYPR

Simple CMS

by Simple CMS

CVEs (146)

  • CVE-2018-10086HigApr 13, 2018
    risk 0.47cvss 7.2epss 0.02

    CMS Made Simple (CMSMS) through 2.2.7 contains an arbitrary code execution vulnerability in the admin dashboard because the implementation uses "eval('function testfunction'.rand()" and it is possible to bypass certain restrictions on these "testfunction" functions.

  • CVE-2020-37238MedMay 16, 2026
    risk 0.42cvss 6.4epss 0.00

    CMS Made Simple 2.2.15 contains a stored cross-site scripting vulnerability that allows authenticated users with Content Manager access to inject malicious scripts through SVG file uploads. Attackers can upload SVG files containing embedded JavaScript to the file manager, which…

  • CVE-2018-10520MedApr 27, 2018
    risk 0.42cvss 6.5epss 0.01

    In CMS Made Simple (CMSMS) through 2.2.7, the "module remove" operation in the admin dashboard contains an arbitrary file deletion vulnerability that can cause DoS, exploitable by an admin user, because the attacker can remove all lib/ files in all directories.

  • CVE-2018-10518MedApr 27, 2018
    risk 0.42cvss 6.5epss 0.01

    In CMS Made Simple (CMSMS) through 2.2.7, the "file delete" operation in the admin dashboard contains an arbitrary file deletion vulnerability that can cause DoS, exploitable by an admin user, because the attacker can remove all lib/ files in all directories.

  • CVE-2018-10516MedApr 27, 2018
    risk 0.42cvss 6.5epss 0.01

    In CMS Made Simple (CMSMS) through 2.2.7, the "file rename" operation in the admin dashboard contains a sensitive information disclosure vulnerability, exploitable by an admin user, that can cause DoS by moving config.php to the upload/ directory.

  • CVE-2017-16784MedNov 10, 2017
    risk 0.40cvss 6.1epss 0.01

    In CMS Made Simple 2.2.2, there is Reflected XSS via the cntnt01detailtemplate parameter.

  • CVE-2017-9668MedJun 18, 2017
    risk 0.40cvss 6.1epss 0.01

    In admin\addgroup.php in CMS Made Simple 2.1.6, when adding a user group, there is no XSS filtering, resulting in storage-type XSS generation, via the description parameter in an addgroup action.

  • CVE-2018-10523MedApr 27, 2018
    risk 0.35cvss 5.3epss 0.01

    CMS Made Simple (CMSMS) through 2.2.7 contains a physical path leakage Vulnerability via /modules/DesignManager/action.ajax_get_templates.php, /modules/DesignManager/action.ajax_get_stylesheets.php, /modules/FileManager/dunzip.php, or /modules/FileManager/untgz.php.

  • CVE-2018-9921MedApr 23, 2018
    risk 0.35cvss 5.3epss 0.01

    In CMS Made Simple 2.2.7, a Directory Traversal issue makes it possible to determine the existence of files and directories outside the web-site installation directory, and determine whether a file has contents matching a specified checksum. The attack uses an…

  • CVE-2018-10082MedApr 13, 2018
    risk 0.35cvss 5.3epss 0.01

    CMS Made Simple (CMSMS) through 2.2.7 allows physical path leakage via an invalid /index.php?page= value, a crafted URI starting with /index.php?mact=Search, or a direct request to /admin/header.php, /admin/footer.php, /lib/tasks/class.ClearCache.task.php, or…

  • CVE-2017-16799MedNov 12, 2017
    risk 0.35cvss 5.4epss 0.00

    In CMS Made Simple 2.2.3.1, in modules/New/action.addcategory.php, stored XSS is possible via the m1_name parameter to admin/moduleinterface.php during addition of a category, a related issue to CVE-2010-3882.

  • CVE-2017-16798MedNov 12, 2017
    risk 0.35cvss 5.4epss 0.01

    In CMS Made Simple 2.2.3.1, the is_file_acceptable function in modules/FileManager/action.upload.php only blocks file extensions that begin or end with a "php" substring, which allows remote attackers to bypass intended access restrictions or trigger XSS via other extensions, as…

  • CVE-2016-2784MedMay 26, 2016
    risk 0.34cvss 4.7epss 0.02

    CMS Made Simple 2.x before 2.1.3 and 1.x before 1.12.2, when Smarty Cache is activated, allow remote attackers to conduct cache poisoning attacks, modify links, and conduct cross-site scripting (XSS) attacks via a crafted HTTP Host header in a request.

  • CVE-2018-10522MedApr 27, 2018
    risk 0.32cvss 4.9epss 0.01

    In CMS Made Simple (CMSMS) through 2.2.7, the "file view" operation in the admin dashboard contains a sensitive information disclosure vulnerability, exploitable by ordinary users, because the product exposes unrestricted access to the PHP file_get_contents function.

  • CVE-2017-11405MedJul 18, 2017
    risk 0.32cvss 4.9epss 0.01

    In CMS Made Simple (CMSMS) 2.2.2, remote authenticated administrators can upload a .php file via a CMSContentManager action to admin/moduleinterface.php, followed by a FilePicker action to admin/moduleinterface.php in which type=image is changed to type=file.

  • CVE-2017-11404MedJul 18, 2017
    risk 0.32cvss 4.9epss 0.01

    In CMS Made Simple (CMSMS) 2.2.2, remote authenticated administrators can upload a .php file via a FileManager action to admin/moduleinterface.php.

  • CVE-2026-5203MedMar 31, 2026
    risk 0.31cvss 4.7epss 0.00

    A vulnerability was found in CMS Made Simple up to 2.2.22. This impacts the function _copyFilesToFolder in the library modules/UserGuide/lib/class.UserGuideImporterExporter.php of the component UserGuide Module XML Import. The manipulation results in path traversal. It is…

  • CVE-2018-10033MedApr 11, 2018
    risk 0.31cvss 4.8epss 0.01

    CMS Made Simple (aka CMSMS) 2.2.7 has Stored XSS in admin/siteprefs.php via the metadata parameter.

  • CVE-2018-10032MedApr 11, 2018
    risk 0.31cvss 4.8epss 0.01

    CMS Made Simple (aka CMSMS) 2.2.7 has Reflected XSS in admin/moduleinterface.php via the m1_version parameter.

  • CVE-2018-10029MedApr 11, 2018
    risk 0.31cvss 4.8epss 0.01

    CMS Made Simple (aka CMSMS) 2.2.7 has Reflected XSS in admin/moduleinterface.php via the m1_name parameter, related to moduledepends, a different vulnerability than CVE-2017-16799.

Page 2 of 8